8.8

CVE-2021-28139

The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly restrict the Feature Page upon reception of an LMP Feature Response Extended packet, allowing attackers in radio range to trigger arbitrary code execution in ESP32 via a crafted Extended Features bitfield payload.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EspressifEsp-idf Version <= 4.4
   EspressifEsp32 Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.29% 0.665
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 8.3 6.5 10
AV:A/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://github.com/espressif/esp-idf
Third Party Advisory
Product
https://github.com/espressif/esp32-bt-lib
Third Party Advisory
Product
https://dl.packetstormsecurity.net/papers/general/braktooth.pdf
Third Party Advisory
Technical Description
https://www.espressif.com/en/products/socs/esp32
Vendor Advisory
Product